Skip to content

Latest commit

 

History

400 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

stapeln

Visual Container Stack Designer for Verified Containers

License: MPL-2.0 ReScript Elixir Idris2 OpenSSF Scorecard OpenSSF Best Practices

Licensing: MPL-2.0 for code, CC-BY-SA-4.0 for documentation — see LICENSING.adoc. Badges wanted and pending restoration: docs/BADGES.adoc.

"Containers for People Who Hate Containers"

Product Goal

A 12-year-old who is reasonably IT-capable can help their parents build a secure container stack. That means no prior container knowledge is required, and security guidance is clear, visual, and actionable.

Current Status

Measured completion: ~48% (2026-08-07, commit bc04e22)

STATUS.adoc is the canonical source of truth — it records only claims backed by a file read, a command run, or a CI query, and it names the command so you can reproduce the number. DEBT.adoc indexes known debt across licence, documentation, code, proof, test, CI/CD and supply chain.

A per-component table used to live here. It drifted six months out of date and was wrong in both directions — understating the Idris2 proofs (called "stubs"; there are 8 genuine modules with zero escape hatches), miniKanren, VeriSimDB and authentication (all called "not started"; all substantial), while overstating compliance. Rather than maintain two tables that disagree, this one is gone. Highlights only:

  • Works: 41 REST routes + Absinthe GraphQL; 10 UI tabs (TEA); full-fidelity design persistence and working security-scan / gap-analysis (both fixed in #17); 8 honest Idris2 ABI proofs; real Ed25519/SHA-256 in Zig; six code-generation emitters

  • Missing: no mix test gate on GitHub; scripts/readiness-check.sh invoked by nothing; no persistent database (in-memory GenServer only); five uninitialised container-stack/ submodules

  • Tests: 245 executable cases (122 ExUnit · 107 Deno · 16 Zig) + 8 Idris2 proof modules

This repo focuses on the stapeln app UI. The DOM-mounter workstream has been extracted to a separate repo: /var$REPOS_DIR/stapeln-dom-mounter.

What is stapeln?

stapeln (Swedish for "the stack") is a visual drag-and-drop designer for creating secure container stacks. It combines:

  • 🎨 Game-like UI - Choose components like customizing a spaceship

  • 🛡️ Built-in Security - Real-time attack surface analysis

  • 🔍 Smart Validation - miniKanren reasoning engine catches vulnerabilities

  • Accessibility First - WCAG 2.3 AAA compliance

  • 🔥 OWASP Integration - ModSecurity firewall with ephemeral pinholes

  • 📊 Multi-Modal Database - VeriSimDB (6 modalities)

  • 📝 Attested Documentation - A2ML with cryptographic signatures

  • Self-Validating Configs - K9-SVC Nickel contracts

"If you have to read the manual, we failed."

— UX Manifesto

Key Features

Four Visual Views

  1. Paragon View (Vertical Stack)

    • Supply chain hierarchy from Cerro Torre → containers → provenance

    • Gap analysis sidebar shows security issues

    • Real-time validation

    • GParted-style vertical block layout

  2. Cisco View (Network Topology)

    • Drag-and-drop components onto canvas

    • Draw connection lines between services

    • Simulation mode with animated packet flow

    • Configure ports visually (no CLI commands!)

    • Multiple shapes: box, oval, gateway, nested

  3. Lago Grey Designer (Base Image Designer)

    • Visual minimal Linux distribution designer (Alpine/Chainguard alternative)

    • Interactive ice formation catalog (Floes < 1MB, Icebergs 1-75MB, Glaciers 75MB+)

    • Real-time size calculation and competitive comparison

    • Security stack indicators (post-quantum + classical crypto)

    • Base image selection (Distroless, Alpine, Scratch)

    • Export to .tar.gz with triple cryptographic signatures

    • 14.6 MB minimal image achieved (vs 60MB Alpine)

  4. Settings

    • Defaults and preferences

    • Runtime selection (Podman/Docker/nerdctl)

    • Accessibility options

    • Smart defaults (hyperpolymath best practices)

Security Features

  • Attack Surface Analyzer - Real-time security scoring (game-like stats!)

  • miniKanren Engine - Deterministic vulnerability detection (no AI hallucinations!)

  • OWASP ModSecurity CRS - Web application firewall (Paranoia Level 3)

  • Ephemeral Pinholes - Temporary firewall openings with auto-expiry (30s to 24h)

  • CVE Integration - Daily updates from NIST NVD

  • Gap Analysis - Shows problems before deployment

  • OWASP Top 10 Compliance - Built-in rule checking

  • CIS Benchmarks - Industry standards

  • Provenance Chains - Full audit trail (why something is flagged)

Database & Documentation

  • VeriSimDB - Multi-modal storage (graph, vector, tensor, semantic, document, temporal)

  • A2ML - Attested Markup Language for verified documentation (lax → checked → attested)

  • K9-SVC - Self-validating component configurations (Kennel → Yard → Hunt security levels)

  • Rekor Integration - Signature verification via transparency log

Game-Like UX

Like customizing a spaceship in a game:

  • ✅ Real-time security score (Security: ████████░░░░ 67/100)

  • ✅ Visual stat bars (Performance, Reliability, Compliance)

  • ✅ Impact indicators (⬆️ Security +15 points)

  • ✅ Color-coded risk levels (🔴 Critical, 🟠 High, 🟡 Medium, ✅ Safe)

  • ✅ One-click auto-fix for vulnerabilities

  • ✅ Simulation mode (test before deploying!)

Tech Stack

Layer Technology

Frontend

affinescript-TEA (The Elm Architecture) + Deno

Backend

Elixir (Phoenix) + GraphQL (Absinthe)

Security Reasoning

miniKanren (Guile Scheme) + OWASP Rules

Database

VeriSimDB (6 modalities: graph, vector, tensor, semantic, document, temporal)

Documentation

A2ML (Attested Markup Language) with Idris2 backend

Config Validation

K9-SVC (Nickel contracts)

Validation

Idris2 proofs + Ephapax linear types

Firewall

firewalld/nftables + ephemeral pinholes

WAF

OWASP ModSecurity Core Rule Set v4.0

Auth

PAM (system user verification)

Signature Verification

Rekor transparency log

Architecture

The Elm Architecture (TEA)

All state transitions are pure functions:

type model = { /* app state */ }
type msg = AddComponent | DragMove | Deploy | Simulate | ...
let update: (model, msg) => (model, effect<msg>)
let view: model => React.element

Time-travel debugging. Fully testable. Predictable.

Security Reasoning (miniKanren)

Deterministic logic programming for security analysis:

(define (expose-ssh-to-interneto component)
  "Rule: SSH port 22 must not be exposed to internet"
  (fresh (port interface)
    (exposed-porto component port interface)
    (== port 22)
    (== interface 'public)))

;; Query violations
(run* (component)
  (expose-ssh-to-interneto component))
;; => (nginx-1 svalinn-1)  ; VIOLATIONS!

Why miniKanren, not an SLM?

  • ✅ Deterministic (same input → same output)

  • ✅ Explainable (full provenance chain)

  • ✅ Instantly updateable (new CVEs added immediately)

  • ✅ No hallucinations (can’t invent fake CVEs)

  • ✅ Fast (milliseconds, not seconds)

  • ✅ Small (< 10 MB, no GPU needed)

Ephemeral Pinholes (Elixir)

Temporary firewall openings with auto-expiry:

# Open port 8080 for 5 minutes
{:ok, pinhole_id} = EphemeralPinhole.open(8080, 300)

# Auto-closes after 300 seconds
# Audit logged to VeriSimDB
# Can manually close early
:ok = EphemeralPinhole.close(pinhole_id)

Multi-Modal Database (VeriSimDB)

# Store stack with multiple modalities
VeriSim.insert(%{
  uuid: "stack-abc123",
  modalities: [:graph, :semantic, :temporal],
  data: %{
    graph: {"stack:abc123", "stapeln:hasComponent", "comp:nginx"},
    semantic: "<http://example.org/stack/abc123> rdf:type stapeln:Stack",
    temporal: %{timestamp: DateTime.utc_now(), event: "created"}
  }
})

# Query with SPARQL
VeriSim.sparql_query("""
  SELECT ?component WHERE {
    ?stack stapeln:hasComponent ?component .
    ?component stapeln:exposesPort 22 .
  }
""")

Quick Start

Prerequisites

  • Deno 2.0+

  • Guile Scheme 3.0+ (for miniKanren)

  • Elixir 1.17+ / Erlang 27+

  • firewalld or nftables

  • Podman or Docker

  • VeriSimDB (optional: federated or standalone)

Installation

# Clone repository
git clone https://github.com/hyperpolymath/stapeln.git
cd stapeln

# Frontend setup (Deno, no npm!)
cd frontend
deno install --allow-read --allow-write --allow-env --allow-run -n affinescript npm:affinescript@11
deno task build

# Backend setup (Elixir)
cd backend
mix deps.get
mix ecto.setup

# Security engine setup (miniKanren)
cd security-rules
guile -s setup.scm

# Firewall setup
sudo ./setup-firewall.sh

# Start all services
./dev.sh

First Run

  1. Open browser: http://localhost:8000

  2. Login with your system user credentials (PAM authentication)

  3. Drag nginx from palette to canvas

  4. Configure ports with visual toggles (no CLI!)

  5. See real-time security scoring

  6. Click [Simulate] to test with packet animation

  7. Click [Deploy] when ready

Usage

Page 1: Paragon View

Vertical stack visualization:

┏━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Cerro Torre (Build)      ┃  ✅ Active
┗━━━━━━━━━━━━━━━━━━━━━━━━━━┛
            ▼
┌──────────────────────────┐
│ Svalinn (Gateway)        │  ⚠️  Port 22 exposed
└──────────────────────────┘
            ▼
┌──────────────────────────┐
│ nginx (Web Server)       │  ✅ Healthy
└──────────────────────────┘
            ▼
┌──────────────────────────┐
│ postgres (Database)      │  ❌ No backup volume
└──────────────────────────┘
            ▼
╔══════════════════════════╗
║ Supply Chain             ║  ✅ Verified
╚══════════════════════════╝

Gap Analysis Sidebar: * ❌ CRITICAL: SSH port 22 exposed * ⚠️ HIGH: No backup volume * 💡 RECOMMENDATION: Add health checks

Page 2: Cisco View

Network topology with drag-and-drop:

     Internet ☁️
         │
         ▼
  ┏━━━━━━━━━━━┓
  ┃ Firewall  ┃ 🔥
  ┗━━━━━━━━━━━┛
         │
         ▼
  ┌───────────┐
  │  nginx    │ 🌐
  │  :80 🔓   │ ⚠️  Insecure!
  └───────────┘
         │
         ▼
  ┌───────────┐
  │ postgres  │ 🗄️
  │ :5432 🔒  │
  └───────────┘

Configuration Panel: * Port 80: ○ Closed ● Open ○ Ephemeral * Security Score: 🟡 67/100 * [Auto-Fix Issues] [Simulate] [Deploy]

Page 3: Settings

  • Default Runtime: Podman / Docker / nerdctl

  • Auto-verify Signatures: ✅

  • Require SBOM: ✅

  • Default CPU Limit: 1 core

  • Theme: System / Light / Dark

Security

stapeln implements defense-in-depth:

Layers

  1. OWASP ModSecurity CRS - WAF at gateway (Paranoia Level 3)

  2. firewalld default-deny - Whitelist-only

  3. miniKanren reasoning - Deterministic vulnerability detection

  4. CVE daily sync - NIST NVD integration

  5. Ephemeral pinholes - Temporary, auto-expiring firewall rules

  6. PAM authentication - System user verification

  7. Audit logging - VeriSimDB temporal modality

  8. Signature verification - Rekor transparency log

  9. SBOM enforcement - Supply chain verification

  10. Gap analysis - Pre-deployment security checks

Current Compliance

Standard Status Score

OWASP Top 10 2021

🟡 Partial

6/10 (→ 10/10 by v1.0)

CIS Benchmarks

🟠 In Progress

12/20 (→ 20/20 by v1.0)

NIST Cybersecurity

🟠 In Progress

8/15 (→ 15/15 by v1.0)

WCAG 2.3 AAA

✅ Complete

100%

OpenSSF Scorecard

✅ Complete

100%

Post-Quantum Crypto

❌ Pending

0% (→ 100% by v1.0)

Target: 100% across all standards before 1.0 release

Post-Quantum Crypto (Roadmap)

Planned upgrades:

  • Dilithium5-AES (ML-DSA-87) for signatures

  • Kyber-1024 (ML-KEM-1024) for key exchange

  • Ed448 + Dilithium5 hybrid mode

  • SPHINCS+ as backup

  • HTTP/3 + QUIC migration

  • SHAKE3-512 hashing

Accessibility

stapeln is WCAG 2.3 AAA compliant:

  • ✅ Full keyboard navigation (no mouse required)

  • ✅ Screen reader optimized (NVDA, JAWS, Orca tested)

  • ✅ Braille display annotations

  • ✅ Semantic XML + ARIA labels

  • ✅ 7:1 contrast ratio (21:1 for critical elements)

  • ✅ Reduced motion support

  • ✅ System-aware dark/light mode

  • ✅ Captions and transcripts for media

Roadmap

See ROADMAP.adoc for detailed timeline.

Phase 1: Design (Complete) ✅

  • ✅ affinescript-TEA architecture

  • ✅ Three-page UI design

  • ✅ Security specifications

  • ✅ Database integration specs

  • ✅ Game-like UI mockups

  • ✅ miniKanren reasoning engine design

Phase 2: Frontend Implementation (45%) ⚠️

  • ✅ Model, Msg, Update, View (affinescript)

  • ✅ CiscoView, Settings pages

  • ✅ LagoGreyImageDesigner component (921 lines)

  • ✅ Interactive ice formation designer with real-time sizing

  • ✅ Four-page navigation integrated

  • ⚠️ Wire existing views to App.res (immediate)

  • ⚠️ Import/export for designs and images (critical)

  • ⚠️ Build pipeline (podman integration)

  • ⚠️ Attack surface analyzer UI

  • ⚠️ Port configuration panel

  • ⚠️ Security inspector component

  • ⚠️ Simulation mode with packet animation

  • ⚠️ Gap analysis sidebar

  • ⚠️ Auth flow (PAM login)

Phase 3: Backend & Security (20%) ⚠️

  • ❌ miniKanren security engine

  • ⚠️ Elixir Phoenix + GraphQL (MVP endpoints live, production hardening pending)

  • ❌ Ephemeral pinhole GenServer

  • ❌ VeriSimDB integration

  • ❌ A2ML parser

  • ❌ K9-SVC validator

  • ❌ ModSecurity configuration

  • ❌ firewalld rules

Phase 4: Post-Quantum Crypto (0%) ❌

  • ❌ Dilithium5 signatures

  • ❌ Kyber-1024 key exchange

  • ❌ HTTP/3 + QUIC migration

  • ❌ SPHINCS+ backup

  • ❌ SHAKE3-512 hashing

Documentation

Contributing

Areas needing help:

  1. miniKanren security rules (Scheme)

  2. affinescript UI components

  3. Elixir backend (Phoenix)

  4. Accessibility testing

  5. Documentation

  6. Security auditing

License

PMPL-1.0-or-later (Palimpsest License)

Credits

Created by hyperpolymath

Designed to convert container-haters into container-users. 🎯

Special thanks to the test user: A government cyberwar officer who loathes containerization. If he can use stapeln successfully, anyone can.


Built with ❤️ and formal verification

Architecture

See TOPOLOGY.adoc for a visual architecture map and completion dashboard.

About

Compiles a drag-and-drop container topology into a verified deployment bundle: topology validation, attack-surface and gap analysis, six code-generation targets, and an Idris2-proven ABI. Podman-only, Containerfiles never Dockerfiles.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages